v2.2.0
Security release.
Fixes
- Sync client proxy was bypassed. The proxy was passed to
requestsas a bare string, which it silently ignores, so requests went out directly from the real IP. It is now passed as a{"http": ..., "https": ...}mapping. - Off-by-one in
Proxy.get_random_proxy: it could pick a port outside the configured range. - Private keys are no longer shown in
repr(Account). - Async requests no longer log request data, and a debug
printinNodeExceptionwas removed.
New
expected_chain_idparameter: transactions are signed only if the node reports this chain id.set_abi(code, abi): use a trusted local ABI instead of the one served by the node.rpc_hostis validated: it must be anhttp(s)URL, and plain HTTP to a non-local host emits a warning.
Breaking changes
- Async requests now raise
NodeExceptionon any non-2xx response, as the sync ones do. Before, they returned the error body. - An
rpc_hostwithout a scheme now raisesValueError.
Dependencies
Raised minimum versions: aiohttp>=3.12.14, requests>=2.32.4, pycryptodome>=3.19.1.
Install: pip install -U eosapi-async==2.2.0